Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations Version 3.7.6 and 3.8.2 restrict such illegitimate use of IMAP literals.
History

Thu, 06 Feb 2025 11:30:00 +0000

Type Values Removed Values Added
Description Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations Version 3.7.6 and 3.8.2 restrict such illegitimate use of IMAP literals.
Title Apache James: denial of service through the use of IMAP literals
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-02-12T19:51:10.228Z

Reserved: 2024-06-06T07:07:32.731Z

Link: CVE-2024-37358

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-02-06T12:15:26.343

Modified: 2025-02-06T12:15:26.343

Link: CVE-2024-37358

cve-icon Redhat

No data.